Malicious
Malicious

bccab38d9c9a08297941cbad5da9d539

VBScript
MD5: bccab38d9c9a08297941cbad5da9d539
Size: 175 B
text/vbscript
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 bccab38d9c9a08297941cbad5da9d539
Sha1 4c8a93abafc9fe108161960412f2bfeef69ea452
Sha256 4f75b70ef696ec050a6ee5f6be7bd7be445526aa5a3b23f5340ecc097281ca11
Sha384 da85149a993f5b5e894fd365081d547ab606ff3490cc906e26d3dc85c4224610367882d26afb5ec64365a4a6b0e7d102
Sha512 9c375f584fe74fe01697c1a65bca2a26655e81d3b12a8fdd4dcb5e845b32da5f8a36f160df1cb3fb65d08551e511ec4b55fce7b1685ef4efd3aa49eac29e37f9
SSDeep 3:jblYFFEm8nhQBgSSJJFIGF7dN0PbKuV2qbqSgBJlQpaKnJvXpv:ju3NqhMs8GFIFOfS0G
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path scr:vbs~T1027~T1059.005>scr:bat>scr:ps1~T1027~T1059.001~T1105
Shape scr:vbs>scr:bat>scr:ps1
malicious 3 nodes
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
Deobfuscated PowerShell UNKNWOWNmalicious
irm "huhuhuhuhuhuhuhuhuhuhu
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
Config. Field Value
URL in PowerShell #1 http:/huhuhuhuhuhuhuhuhuhuhu
We extracted this malware's full configuration (C2, credentials, campaign IDs…).
Unlock with Essential
Trace COM ordonnée UNKNWOWNmalicious
line 1huhuhuhuhuhuhuhuhuhuhu
bccab38d9c9a08297941cbad5da9d539
URLs in VB Code - #1 URIsuspect
http:/huhuhuhuhuhuhuhuhuhuhu
bccab38d9c9a08297941cbad5da9d539
Deobfuscated PowerShell UNKNWOWNmalicious
irm "huhuhuhuhuhuhuhuhuhuhu
bccab38d9c9a08297941cbad5da9d539 › bccab38d9c9a08297941cbad5da9d539.deobfuscated.vbs › [Command #0] › [PowerShell Command]
Full artefact values (URLs, paths, registry keys, scripts…) are available with Essential.
Unlock with Essential
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙